Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Cyber Essentials cost 2026 by organisation size: micro £320, small £440, medium £500, large £600 plus VAT

Cyber Essentials Cost 2026: The Complete UK Price Guide

The Cyber Essentials cost that catches organisations out is never the certification fee. That number is fixed, published and small — between £320 and £600 plus VAT, depending on how many people you employ. The expensive part sits either side of it: the licences you buy in order to pass, the machines you replace because nobody supports them any more, and the second attempt you pay for in full if the assessor fails you.

This guide splits the 2026 Cyber Essentials cost into the figures you can look up on IASME’s own site and the figures you have to estimate for your own estate. Every published number below comes from IASME or the UK government. Every estimate is labelled as one.

What the Cyber Essentials cost actually buys

Cyber Essentials is a verified self-assessment. You answer a question set, a qualified assessor from IASME reviews your answers, and you get a pass or a fail. There is no vulnerability scan and no site visit at this level. Instead, a board member signs a declaration confirming the answers are true.

The Cyber Essentials cost you pay to IASME covers a defined package:

  • Access to the assessment portal and the current question set
  • Review of your answers by a certified assessor
  • One pass or fail verdict, plus two working days to correct simple issues and resubmit at no extra charge
  • The certificate and badge if you pass, and a listing on the certified organisations register
  • Free cyber liability insurance, if you are domiciled in the UK or Crown Dependencies, turn over less than £20m, certify your whole organisation and opt in

What it does not cover is everything that makes you certifiable in the first place, the Cyber Essentials Plus audit, and any consultancy. If you still fail after the two-day correction window, IASME’s position is unambiguous: you reapply and pay the assessment fee again.

Cyber Essentials cost by organisation size in 2026

Unlike almost every other certification in this space, the Cyber Essentials cost is set centrally. IASME publishes a tiered fee based on the UK government’s employee-count definitions, so a certification body cannot mark the assessment fee up or down. It can only sell its own services around it.

Organisation sizeEmployeesIASME fee (ex VAT)IASME’s published USD equivalent
Micro0–9£320$460
Small10–49£440$630
Medium50–249£500$710
Large250 or more£600$850
IASME assessment fees, published September 2026. VAT is charged on top.

Two things follow from that table. First, headcount is the only variable: a 40-person software firm with a sprawling cloud estate pays the same £440 as a 40-person joinery business with a dozen laptops. Second, the USD and EUR figures IASME shows alongside the sterling prices float with exchange rates, so treat them as indicative and budget in pounds.

Certificates expire after 12 months. Cyber Essentials is annually renewable, and you re-enter every answer each year rather than confirming last year’s, because IASME treats that as your annual review. Budget the fee as a recurring line, not a one-off.

Cyber Essentials Plus: the price nobody publishes

Cyber Essentials Plus tests the same five controls, but independently. A technical assessor samples your devices and verifies the controls actually work. Because that consumes assessor time and depends entirely on the size and shape of your network, IASME does not set the price. Each Plus assessment is quoted individually by a licensed certification body, and IASME runs a form that emails you quotes from three different bodies so you can compare.

Certification bodies that publish rate cards give a usable sense of the range. One publishes combined prices from £1,240 plus VAT for a micro organisation up to £1,800 for a large one, with the Plus audit alone starting at £920 plus VAT if you already hold a current certificate. Across providers who publish figures at all, quotes generally land between roughly £1,200 and £4,250 plus VAT, driven by device count and scope complexity. Treat that as a market observation rather than a rate card.

Cyber EssentialsCyber Essentials Plus
How it is assessedVerified self-assessment, reviewed by an IASME assessorIndependent technical audit with device sampling
Who sets the priceIASME, centrallyYour certification body, per quote
2026 price£320–£600 + VATQuoted; published rate cards commonly £1,200–£4,250 + VAT
Includes the IASME fee?Yes, it is the feeNo — the assessment fee is payable as well
Certificate validity12 months12 months

One scheduling detail is worth real money. If you achieved the verified self-assessment less than three months before certifying to Cyber Essentials Plus, you do not repeat the self-assessment stage. Run the two close together and you avoid duplicating work; let them drift apart and you pay for the questionnaire stage twice.

Five Cyber Essentials cost items that never make the budget

  • Multi-factor authentication licensing. MFA on cloud services is not optional under the current question set. If your plan tier does not include it, the upgrade is a permanent per-user cost, not a one-off certification expense.
  • End-of-life hardware and operating systems. Anything no longer receiving security updates must be replaced, isolated or removed from scope. For most organisations this is the single largest line, and it is capital spend rather than a fee.
  • Patching discipline. High and critical vulnerabilities must be fixed within 14 days. Meeting that reliably usually means patch tooling or a managed service, not goodwill.
  • Internal time. Gathering evidence, confirming device inventories and chasing answers across teams typically absorbs two to five working days for a first certification. That is an estimate, and it scales with how scattered your asset records are.
  • A failed attempt. After the two working days you get to fix simple issues, a failure means reapplying and paying the full fee again. On the large tier that is another £600 plus VAT.

What Danzell changed in April 2026

IASME published the Danzell question set on 13 February 2026, and it applies to all assessment accounts created after 26 April 2026. Organisations with an active account created before that date were given six months to certify against the previous requirements, which puts the end of that transition in late October 2026. If you are still sitting on an older account, that window is closing.

Danzell arrives with version 3.3 of the Requirements for IT Infrastructure. The five controls did not change, but the scoping rules tightened in ways that move the Cyber Essentials cost for some organisations:

  • Cloud services cannot be excluded from scope. If your data or services are hosted there, they are in.
  • Exclusions must now be justified, and you must explain how excluded networks are segregated from in-scope systems.
  • The old web applications section is now application development, and it references the UK government’s Software Security Code of Practice.
  • For Cyber Essentials Plus, updates identified during the audit must be applied across the whole scope, not only to the sampled devices. That is a direct response to organisations patching just the machines being tested.

The practical effect is that narrowing your scope to save money has become harder to do honestly. Our guide to the Cyber Essentials questionnaire covers the auto-fail answers in detail.

How to reduce your Cyber Essentials cost honestly

Almost all the room to move is in scope and preparation rather than negotiation, because the assessment fee is fixed and there is nothing to haggle over.

  • Retire end-of-life devices before you apply, not after the assessor finds them.
  • Use the free Cyber Essentials Readiness Tool that IASME and the NCSC publish before you buy anything.
  • Consolidate the device estate. Fewer platforms means fewer configurations to evidence and, for Plus, a smaller sample.
  • Book Plus within three months of the self-assessment so you do not repeat the questionnaire stage.
  • Certify the whole organisation. A carved-out scope can look cheaper, but it forfeits the free insurance and tends to raise questions with the customer who asked for the certificate.

What does not work is answering optimistically. A failure costs a full re-fee, and under Danzell the marking is less forgiving than it was.

Is the Cyber Essentials cost justified?

For most UK organisations the question answers itself commercially. Under PPN 014, in-scope public bodies must ensure suppliers meet defined technical requirements on higher-risk contracts, and the note’s stated position is that requiring Cyber Essentials or Cyber Essentials Plus is the most effective way to do that. Suppliers holding neither certificate have to demonstrate equivalent controls by other means, which is slower and far less convincing than a certificate.

Set against that, the Cyber Essentials cost is modest. A small firm pays £440 plus VAT for a certificate that unblocks tenders, satisfies a growing share of private-sector supplier questionnaires, and carries £25,000 of cyber liability cover if it qualifies. That insurance is genuinely limited — £25,000 of indemnity with a £1,000 excess, rising to £5,000 for claims arising from activity in the USA or Canada, and no cover for money stolen electronically — so treat it as a useful extra rather than a reason to certify.

If you are weighing this against a full management system, our breakdown of ISO 27001 certification cost puts the gap in perspective. The two schemes are an order of magnitude apart.

Cyber Essentials cost FAQ

How much does Cyber Essentials cost for a 30-person company?

£440 plus VAT. Thirty employees puts you in IASME’s small tier, which spans 10 to 49 people.

Does the Cyber Essentials cost include Cyber Essentials Plus?

No. The Plus audit is quoted and invoiced separately by your certification body, and the IASME assessment fee is still payable on top.

What happens to the cost if we fail the assessment?

You get two working days to review the assessor’s feedback and correct simple issues, and the reassessment inside that window is free. Miss it and you reapply and pay the assessment fee again.

Do we pay the full Cyber Essentials cost every year?

Yes. Certificates expire after 12 months and renewal is a fresh assessment. You re-enter every answer rather than confirming the previous year’s.

Can a certification body charge less than the IASME fee?

No. The assessment fee goes to IASME and is fixed by tier. What varies between bodies is the support, remediation help and Plus audit they sell around it.

Where this leaves you

Budget the Cyber Essentials cost as three separate things: a fixed annual IASME fee you can look up today, a quoted Plus audit if a customer demands one, and a remediation bill that depends entirely on how old your device estate is. The first is trivial. The third is where the money actually goes.

If the documentation side is what is slowing you down, our Comprehensive Cyber Essentials UK Toolkit gives you 25 editable templates covering the policies and records assessors expect to see, for $99. It will not patch your servers, but it removes the blank-page problem.

Start with the controls themselves. Our guide to Cyber Essentials certification explains what each of the five controls actually requires, and Cyber Essentials Plus covers what the technical audit adds.

References

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.